Worm

What is “Worm.Win32.AutoRun.gms”?

Malware Removal

The Worm.Win32.AutoRun.gms is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.AutoRun.gms virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.AutoRun.gms?


File Info:

name: 940E151057DB293D1827.mlw
path: /opt/CAPEv2/storage/binaries/3e8363e450dd7a5aeefe2e72bda3e43d0a13ce2162966bc24b45ab700c8b9400
crc32: 5FCE8727
md5: 940e151057db293d1827a5a9c41a898c
sha1: 67e160a9cf70c079f09b624e2719710c19e44c87
sha256: 3e8363e450dd7a5aeefe2e72bda3e43d0a13ce2162966bc24b45ab700c8b9400
sha512: 94f58ad10838c0bb0aff7e0885d05e3a38e35bda4d99346138eaf4875606132a45135cb7a84bcc4c1480e202bf84d083ce5988bd33f83694b710be197b61f072
ssdeep: 3072:QVOZBWAJCbL2+LaEdtQqXjuVx3ucPsunjzc5ULc5uszD9dDy6j6:QIZBWAJCbL2+LaEdSVx35P1nnc5ULc5B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0E38E3DFA10611DEDE141793C643A3FBA481E7D0944AA66F7B1464EA0F2BE2B4E4707
sha3_384: dd7921cb440b11445bb418dd8cc06aae5011a97ed54dd753f4275d334c9e267a90098684a2f1c9f6e64be1dbda453e7b
ep_bytes: 6880244000e8eeffffff000000000000
timestamp: 2009-06-13 14:49:05

Version Info:

0: [No Data]

Worm.Win32.AutoRun.gms also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.AutoRun.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.467601
FireEyeGeneric.mg.940e151057db293d
CAT-QuickHealWorm.Autorun.UI3
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacGen:Variant.Zusy.467601
Cylanceunsafe
ZillyaWorm.AutoRun.Win32.351069
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005b31811 )
AlibabaWorm:Win32/AutoRun.23315dfe
K7GWTrojan ( 005b31811 )
BitDefenderThetaGen:NN.ZevbaF.36804.jmX@aCjGCVf
VirITWorm.Win32.AutoRun.GMS
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.EL
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0CD124
Paloaltogeneric.ml
ClamAVWin.Trojan.VB-1074
KasperskyWorm.Win32.AutoRun.gms
BitDefenderGen:Variant.Zusy.467601
NANO-AntivirusTrojan.Win32.AutoRun.wqak
AvastWin32:AutoRun-AXV [Wrm]
TencentWorm.Win32.AutoRun.ka
EmsisoftGen:Variant.Zusy.467601 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.64538
VIPREGen:Variant.Zusy.467601
TrendMicroTROJ_GEN.R002C0CD124
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-D
IkarusTrojan.VB
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/AutoRun.L.gen!Eldorado
Antiy-AVLWorm/Win32.AutoRun
KingsoftWin32.Worm.AutoRun.gms
MicrosoftWorm:Win32/Autorun.UE
XcitiumWorm.Win32.Autorun.VB_EL0@1isj9n
ArcabitTrojan.Zusy.D72291
ViRobotWorm.Win32.Autorun.151552.AK
ZoneAlarmWorm.Win32.AutoRun.gms
GDataGen:Variant.Zusy.467601
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.AutoRun.R485143
McAfeeW32/Autorun.worm.gk
MAXmalware (ai score=86)
VBA32OScope.Trojan.VB.01580
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Autorun.JQN
RisingTrojan.Win32.VBCode.akg (CLASSIC)
YandexTrojan.GenAsa!vgzaXTv/ojM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBNA.B!tr
AVGWin32:AutoRun-AXV [Wrm]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Autorun.VB

How to remove Worm.Win32.AutoRun.gms?

Worm.Win32.AutoRun.gms removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment